cbcvebase.
CVE-2024-31867
published 2024-04-09

CVE-2024-31867: Improper Input Validation vulnerability in Apache Zeppelin. The attackers can execute malicious queries by setting improper configuration properties to LDAP…

medium6.5CVSS 3.1
AVNACLPRNUINSUCLILAN
Improper Input Validation vulnerability in Apache Zeppelin. The attackers can execute malicious queries by setting improper configuration properties to LDAP search filter. This issue affects Apache Zeppelin: from 0.8.2 before 0.11.1. Users are recommended to upgrade to version 0.11.1, which fixes the issue.

Affected

2 ranges
VendorProductVersion rangeFixed in
apachezeppelin>= 0.8.2 < 0.11.10.11.1
apache_software_foundationapache_zeppelin>= 0.8.2 < 0.11.10.11.1